Signature Verification Flaw in OpenSSL Encrypt Affects Security Protocols
CVE-2026-81700
9.3CRITICAL
What is CVE-2026-81700?
OpenSSL Encrypt versions before 1.4.9 contain a vulnerability in the signature verification process within gpg_runner.verify_detached. This flaw allows the acceptance of revoked and expired keys due to inadequate checks of VALIDSIG status. Attackers can leverage compromised keys, which have been revoked or expired, to bypass signature verification mechanisms. This could lead to the execution of malicious plugins, posing a serious threat to host processes.
Affected Version(s)
openssl_encrypt 0 < 1.4.9
openssl_encrypt 1.4.9
